We have been writing about the California Invasion of Privacy Act (CIPA) for a while now. From demand letters flooding our clients’ inboxes to the wave of class action filings targeting standard website tracking tools, this 1967 wiretapping statute has proven uniquely susceptible to claims that bear little resemblance to the covert surveillance it was
Taft Privacy & Data Security Insights
Updates and analysis from Taft Privacy and Data Security attorneys
Blog Authors
Latest from Taft Privacy & Data Security Insights
AI-Powered Call Transcription Tools Present Class Action BIPA Risk

We have all become accustomed to seeing pop-up notices on our video calls saying that an AI-powered technology is recording us. Sometimes the AI service even appears as a participant. Notwithstanding how commonplace these features have become, a recent decision from a federal court in California may signal that such call transcription services present a…
Federal Court Rules Government’s Anthropic Supply Chain Designation Was Unlawful Retaliation: What Government Contractors Need to Know
This is the third installment in our coverage of the Anthropic/Department of War dispute. Our first alert addressed the Trump administration’s February 27 directives barring federal contractors from using Anthropic and its Claude platform, including Secretary Hegseth’s designation of Anthropic as a supply chain risk to national security and the resulting requirement that all DoW…
Enforcement and Transparency Obligations Under the EU AI Act are Now in Effect

On August 2, 2026, the EU AI Act (the AI Act) entered a new implementation phase with two key developments: (i) the European Commission’s AI Office and Member State authorities began enforcing applicable AI Act requirements, including the rules for general-purpose AI (GPAI) models; and (ii) the AI Act’s Article 50 (transparency obligations) also took…
Coming Soon Near You: New Privacy Laws in Alabama, Louisiana, Oklahoma, and Vermont

A new wave of comprehensive state privacy laws is on the horizon for 2026 and beyond. Alabama, Louisiana, Oklahoma, and Vermont have each enacted consumer data privacy statutes that will come online over the next few years, extending the patchwork and raising the stakes for multi‑state compliance programs.
Below, we provide the general thresholds for…
Just DROPped: A Data Broker Law Update

California’s Delete Request and Opt-Out Platform (DROP) requirements went into effect on August 1, 2026, marking a meaningful operational shift for regulated data brokers and a clear reminder that enforcement of the Delete Act is no longer theoretical.
Separately, several other states have advanced their own data broker frameworks. New Jersey introduced an aggressive data…
Children’s Data & Social Media Privacy Laws
Portions of this blog were also co-authored by Taft Summer Associate Ashley Patriquin.

Businesses that provide a website or online services that collect data from or about minors or children should be aware of expanding legal requirements from U.S. states. These laws impose a range of obligations on businesses, including age estimation requirements, heightened privacy…
Internalizing AI Governance: The Practical Thinking So Far

Clients, recent speaking engagements, the explosion of state AI regulation and guidance from financial authorities have all forced me to think and re-think how companies should practically approach their AI governance.
On the one hand, AI-powered tools promise to advance productivity for most tech-powered companies, and most companies find themselves eager to harness the…
California Legislature Takes Aim at CIPA Abuse

We have been writing about the California Invasion of Privacy Act (CIPA) for a while now (and, earlier this year, we predicted this law would continue to be a major issue in 2026).
From demand letters flooding our clients’ inboxes to the wave of litigation targeting standard website tracking tools, this 1967 wiretapping statute…
Changing Tides: A Los Angeles Court Delivers a Major CIPA Defense Win

The California Information Privacy Act (CIPA) has become a go‑to vehicle for plaintiffs’ counsel attacking website tracking technologies, such as cookies, pixels, beacons, chat bots, and video or session replay tools.
Over the last few years, website operators have been hit with a wave of demand letters claiming CIPA violations. But the tide may be…